Re: hiding contacts (ojbect) from directory search (LDAP)

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



basically, what you are saying is that a group of people are able to query
AD for contacts and you dont want that.

so to prevent a group of people to view those contacts while allowing others
you would need to create a group, put those people in that group and assign
DENY to those contacts.


does this apply to a group of users or ALL users? and how large is that
group compared to the total number of users? is it possible that more be
people would belong to that group that is not allowed to view those
contacts?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
<tractng@xxxxxxxxx> wrote in message
news:1156877227.939450.192810@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Jorge,

I am guessing you talking about denying the people/group on group
policy and not under the GAL?

If under the group policy on the OU, should there be an attributes that
you have to enable or just checking the "denying" on the group will do
the trick.


Thanks,
Tnt
Jorge de Almeida Pinto [MVP - DS] wrote:
you will need to modify the permissions of those objects so that that
group
of people cannot retrieve the contacts using a query

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
<tractng@xxxxxxxxx> wrote in message
news:1156606204.214966.26690@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

Can somebody point me to the right directions. I want to hide the
contacts from certain people in the domain. When users search
directory servcice using Outlook expresss,(if a user has a domain
account opens up outlook express, he/she can view all the contacts by
entering the dc=<domain>,dc=<ext> into Search base) they can still see
the contacts.

I have put all the contacts onto one single OU. Is there a way to do
this?


I am not talking about going into the exchange advanced tab and check
hide from exchange address lists.

Thanks,
Tnt




.



Relevant Pages

  • Re: delegate admin rights to an user in an OU
    ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forcing Global Catalog Replication
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... the results of the query to change. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Grant Administrative Access to a Domain Controller
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ... "Jorge Silva" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Grant Administrative Access to a Domain Controller
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ... "Jorge Silva" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Query for disabled users...?
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... I can for example hit the Filter button and use a custom LDAP query... ...
    (microsoft.public.windows.server.active_directory)